Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument pppoeUser leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.3% | — | Totolink Lr1200gb Firmware | 16/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument text leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 3.8% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 4.8% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 4.9% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 4.4% | — | Totolink Lr1200gb Firmware | 8/1/2024 | 17/6/2026 | A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.18% | — | Mediatek Lr12aMediatek Nr15Mediatek Nr16Mediatek Nr17 | 6/11/2023 | 17/6/2026 | In modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction may be also needed for exploitation Patch ID: MOLY01138425; Issue ID: MOLY01138425 (MSV-862). | |
| Modificada | Crítica (9.8) | 8.7% | — | Totolink Lr1200gb Firmware | 31/10/2023 | 17/6/2026 | TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth. | |
| Modificada | Crítica (9.8) | 0.68% | — | Mediatek Lr11Mediatek Lr12aMediatek Lr13Mediatek Nr15+2 | 2/10/2023 | 17/6/2026 | In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID: ALPS08010003. | |
| Modificada | Alta (7.5) | 1.1% | — | Mediatek Lr12aMediatek Lr13Mediatek Nr15Mediatek Nr16 | 8/11/2022 | 17/6/2026 | In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00867883; Issue ID:… | |
| Modificada | Crítica (9.8) | 3.4% | — | Mediatek Lr11Mediatek Lr12Mediatek Lr12aMediatek Lr13+3 | 6/7/2022 | 17/6/2026 | In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | |
| Modificada | Crítica (9.8) | 2.8% | — | Mediatek Lr11Mediatek Lr12Mediatek Lr12aMediatek Lr13+3 | 6/7/2022 | 17/6/2026 | In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00803883; Issue ID: MOLY00803883. | |
| Modificada | Alta (7.5) | 0.74% | — | Mediatek L9Mediatek Lr11Mediatek Lr12Mediatek Lr12a+2 | 4/1/2022 | 17/6/2026 | In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID: ALPS05886933. |